In recent months, children’s online safety and privacy have moved to the top of the EU’s digital agenda. The European Commission is expected to outline its proposal on minors’ access to social media this week, a potentially significant development that would build on the recommendations of the Commission’s Special Panel on child safety online and mounting pressure from Member States.

The EU is not moving in isolation. Similar debates on minors’ access to online platforms, age assurance, and safety-by-design obligations are emerging in other jurisdictions. These include Australia and the United Kingdom, as well as a rapidly developing patchwork of state-level age-verification, app-store, and device-based age-assurance requirements in the United States.

This post provides a horizon-scanning update on the principal regulatory developments at the EU level, selected national developments, and some relevant developments outside the EU.

I. Key EU Developments

A. EU Proposals: Minors’ Access to Social Media and the Digital Fairness Act

At the EU level, attention has increasingly focused on the possible introduction of an EU-wide minimum age for social media. On July 13, the Commission’s Special Panel on child safety online recommended a developmental, age-tiered framework structured around three developmental stages: (i) avoid screens for toddlers (under the age of 3), (ii) supervised, age-appropriate use for children between 3-12 years of age, and (iii) “evolving autonomous use” with mandatory safety features for those between 13-18 years of age. The Special Panel Report recommended that, “[u]ntil they demonstrate that their services are safe by design, social media and other digital services providers should have restricted access to children under the age of 13 in the EU,” while noting that Member States could introduce additional precautionary restrictions for older adolescents. President von der Leyen welcomed the recommended “phased and gradual access” model and confirmed a legislative proposal would be released by the end of the year, with details expected in her State of the Union speech on September 16, 2026.

That proposal may be brought forward alongside, or potentially as part of, the Digital Fairness Act (“DFA”) proposal, which remains on track for Q4 2026. Among other things, the DFA proposal is expected to address personalized advertising directed at minors, influencer marketing, age assurance measures, default safety and privacy settings for children, and platform design features that may contribute to excessive or compulsive use by minors. If minors’ access is folded into the DFA, a consumer-protection law, that would likely mean consumer protection authorities will be tasked with enforcement, which would occur alongside the ongoing work of Digital Services Coordinators (“DSCs”) pursuant to the Digital Services Act (“DSA”), which also contains restrictions designed to protect children on DSA-regulated platforms.

B.   Digital Services Act Enforcement Focus on Minors

For the past several months, the European Commission’s DSA enforcement activity has increasingly focused on the protection of minors online, including issues relating to age assurance, recommender systems, default settings for minors, and features sometimes described as having an “addictive or manipulative design.” This enforcement activity suggests a broader focus on child-safety obligations under Article 28 DSA and core platform design choices, rather than transparency obligations alone.

The Commission’s 2025 Guidelines provide a useful benchmark for platforms accessible to minors to assess compliance with Article 28(1) of the DSA. Recommended measures include private-by-default accounts, adjusted recommender systems, disabling “addictive design” features by default, and the use of proportionate age-assurance methods, including age verification where a national minimum-age rule applies.

C.   EU Age Verification and Age Assurance Initiatives

These recent developments have brought increased attention to age-assurance measures and their associated data protection implications. In February 2025, the European Data Protection Board (“EDPB”) adopted a statement on age assurance, setting out ten principles for the compliant processing of personal data when verifying or estimating a user’s age. The EDPB emphasized that methods should be as minimally intrusive as possible while remaining effective, and that children’s data must be protected throughout.

In parallel, the European Commission is advancing several age-verification solutions. In April 2026, the Commission made available its own age verification solution that can be customized by Member States and market players. The European Commission’s accompanying Recommendation calls on Member States to make the EU age verification solution available by December 31, 2026, either as a standalone app or integrated into the European Digital Identity Wallet. It further encourages coordination among Member States, the Commission, national DSCs, researchers, and civil society. The Recommendation further called for an EU Age Verification Scheme to set common trust and governance requirements for providers, including EU-level lists of compliant solutions and trusted proof-of-age attestation providers. Consistent with that objective, the EU Age Verification Trusted List became available on July 10, 2026, on the eIDAS Dashboard.

D.   Other Developments

The broader EU framework for protecting children online continues to evolve. In particular, the temporary derogation from certain provisions of the ePrivacy Directive, which allows certain communications services to undertake voluntary measures to detect, report, and remove online child sexual abuse material (“CSAM”), has been renewed following a short period of expiration. The renewed temporary framework applies until April 3, 2028, while negotiations on the proposed CSAM Regulation continue.

In addition, the Digital Omnibus on AI introduced new Article 5 prohibitions, applicable from December 2, 2026, on so-called “nudifier” tools and AI systems used to generate child sexual abuse material, reflecting a similar approach adopted in the UK and certain U.S. states.

Finally, the EDPB’s guidance pipeline is worth watching alongside the Commission’s. Its guidelines on children’s data are listed as a priority deliverable in the Board’s 2026-2027 Work Programme, and the minutes of the 121st plenary confirm that drafting is ongoing. This suggests that, as the Commission continues to advance its children’s safety agenda, the EDPB will add a further layer of guidance focused specifically on the protection of children’s personal data.

II. EU Member State-Level Initiatives

Several Member States have taken concrete steps to regulate minors’ access to certain online platforms, although the scope, legal basis, and regulatory model of these initiatives continue to vary significantly. For instance:

  • Austria: In July 2026, the Austrian government proposed legislation restricting access by users under 14 to certain social media platforms. The draft measure would apply to platforms that rely on features such as recommendation algorithms, infinite scrolling and reward systems, while excluding certain interpersonal communication and messaging services. Entry into force currently envisaged for January 2027, with compliance required by March 31, 2027.
  • France: In July 2026, the French Parliament approved legislation restricting social media access for users under 15, following amendments made in response to the Commission’s detailed opinion. Shortly thereafter, the French Constitutional Council blocked the law’s central provision, finding that an undifferentiated restriction applicable to a broad swath of platforms and all users under 15, without regard to platform-specific risks, the child’s age or maturity, or parental involvement, disproportionately interfered with freedom of expression. The Constitutional Council also found that the provision lacked adequate privacy safeguards for the age-verification checks that would have applied to all users, including adults. In response to the decision, the French government indicated that it would prepare a revised legislative proposal as quickly as possible. For more details, see our previous post here.
  • Denmark: On September 7, 2026, the government launched a public consultation on a draft bill establishing a minimum age of 15 for social media platforms, with entry into force projected to occur on July 1, 2027.

Developments in other European jurisdictions, including Greece, Norway and Romania, also illustrate that national age thresholds remain popular legislative pursuits. However, the related verification, supervision, and enforcement mechanisms are not always aligned with the EU’s harmonised legal framework. In particular, their relationship to the DSA and e-Commerce Directive, including with respect to the country-of-origin principle and applicable notification requirements, is often unclear. More specifically:

  • Greece: The Commission issued a detailed opinion on a Greek draft law requiring social-network providers to use “appropriate, proportionate and reliable age-verification methods” to prevent access by users under 15. It found that the prescribed age-verification and optional age-estimation methods would encroach on Article 28(1) DSA, which it considers fully harmonises providers’ age-assurance obligations, and that the proposed notification of suspected infringements by foreign-established platforms would overlap with the DSA’s cooperation mechanism. However, the Commission found no breach of the e-Commerce Directive’s country-of-origin principle because the measure applies generally to domestic and foreign providers.
  • Norway: In relation to Norway’s proposed under-16 restriction, the Commission indicated that the proposed age threshold would not appear to conflict with Article 28 DSA to the extent that the measure is limited to protecting minors, but both the Commission and the EFTA Surveillance Authority raised potential country-of-origin concerns regarding obligations imposed on providers established outside Norway.
  • Romania: In Romania, the national audiovisual regulator has similarly cautioned that proposed legislation aimed at strengthening protections for children under 15 online, including age verification requirements, parental consent mechanisms, restrictions on access to certain online services, and enhanced platform obligations relating to minors, may overlap with the DSA. The regulator recommended clearly distinguishing measures that supplement the EU framework from provisions that merely reproduce existing DSA obligations concerning the protection of minors online.

At the same time, data protection regulators continue to scrutinize the implications of various age assurance tools, given that several of them process personal data such as facial images and combined data across platforms. For example, in March 2026, the Spanish AEPD fined Yoti €950,000 in connection with its Digital ID app, alleging, among other things, that it processed biometric data without a valid Article 9 GDPR condition. As another example, the French data protection authority, the CNIL, has recommended age-verification systems based on independent third-party verification and “double anonymity,” whereby the age-verification provider does not know which service the user is accessing, and the service provider does not receive the user’s identity, to safeguard users’ privacy and personal data.

III. Developments Beyond the EU

Similar debates on minors’ access to online platforms, age assurance, and safety-by-design obligations are emerging in jurisdictions outside the EU, offering useful points of comparison as the EU framework develops. Notable developments in other jurisdictions include:

A.   Australia

Australia was the first country to legislate a strict minimum age for social media, requiring social media platforms to take reasonable steps to prevent users under 16 from holding accounts. The enforcement of the Australian legislation is being closely monitored in the EU, particularly as policymakers assess the practical implications of minimum-age requirements and related age-assurance obligations.

B.   Brazil

Brazil has emerged as one of the most active jurisdictions in this area following the adoption of the Digital Statute of the Child and Adolescent (“Digital ECA”), which entered into force in March 2026. The legislation establishes a comprehensive framework for digital products and services directed at, or likely to be accessed by, children and adolescents, incorporating concepts such as safety-by-design, privacy-by-design, parental supervision tools, age-assurance measures, and restrictions on certain design practices considered harmful to minors. The law also places significant emphasis on the “best interests” of children and adolescents and requires providers to assess and mitigate risks to minors in the digital environment.

Public debate has intensified following several high-profile online safety incidents involving minors. The Brazilian National Data Protection Agency (“ANPD”)—which also serves as the data protection regulator under Brazil’s General Personal Data Protection Law (“LGPD”)—is now increasing Digital ECA enforcement by pursuing both company-specific investigations and collective oversight. On August 21, ANPD issued requests for information in connection with 22 digital platforms, app stores, and GenAI models, in an effort to assess those companies’ compliance with the new law.

C.   Malaysia

Malaysia’s Child Protection Code, adopted under the Online Safety Act 2025, took effect on June 1, 2026. The Code prohibits users under 16 from registering social media accounts and requires licensed platforms with at least eight million users in Malaysia to verify users’ ages using government-issued identification, rather than relying on self-declaration. Existing accounts held by users under 16 are also subject to verification and may be suspended following a grace period. The obligations apply to platforms rather than parents or children. Gaming and communications services are not currently classified as social media and therefore fall outside the Code’s scope.

D.   United Kingdom

The United Kingdom has opted for a more granular regulatory model as it continues to layer on top of the Online Safety Act 2023 (“OSA”) and the Information Commissioner’s Office (“ICO”) Children’s Code. Two new enabling acts that received royal assent in April—the Children’s Wellbeing and Schools Act 2026 and the Crime and Policing Act 2026—introduced several new powers and requirements, including the ability of the Secretary of State to restrict children’s access to specified services or functionalities and new offenses related to nudification tools, non-consensual intimate imagery, and related conduct.

With these new powers, the government announced in June a ban on social media for under-16s and, in July, functionality restrictions such as default midnight-to-6 a.m. curfews, restricted autoplay and personalized feeds for 16-17 year-olds, and mandatory chatbot breaks for under-18s.

Meanwhile, Ofcom launched the third phase of its implementation of the OSA by releasing its Register of Categorised Services and a series of consultations, including on a draft Category 1 Additional Duties Code covering user empowerment, optional identity verification, and safeguards for news, journalistic, and democratic content (for more details, see here). In May, it also confirmed its “hash matching” recommendation for its Illegal Content Codes to combat intimate image abuse, while the government worked with device manufacturers to block access to nude images on devices such as smartphones.

The ICO has also increased its scrutiny of children’s data protection (and, in particular, age assurance) under the Children’s Code and the UK GDPR. In addition to ongoing enforcement activity, in an August 2026 progress update regarding the UK Children’s Code the ICO reported that it was continuing its engagement with major online platforms and had launched a series of risk reviews of 14 age assurance providers, in which it found both areas of good practice and areas that need improvement. In addition, in March, the ICO and Ofcom issued a joint statement on age assurance, emphasizing that age-assurance measures must be both highly effective and compliant with data protection requirements, and that providers should adopt approaches that are proportionate to the risks posed by their services. The joint statement also provided some helpful insights into which forms of age assurance are and are not likely to be effective (for more details, see our blog here).

E.   United States

For more details on recent developments in the U.S., see our blogs here and here.

IV. Looking Ahead

At minimum, the following key developments should be monitored closely over the next several months:

  • The European Commission’s expected proposal on minors’ access to social media, due later in 2026.
  • Increasing enforcement under the EU Digital Services Act focused on minors’ safety, recommender systems, and so-called “addictive design” features.
  • The rollout of EU age-verification solutions and related age-assurance requirements.
  • National initiatives, particularly in France and Austria, which may shape or influence future EU legislation.
  • The European Commission’s forthcoming Digital Fairness Act, which is expected to address digital marketing to minors and other online practices affecting children and consumers.
  • Developments outside the EU, including enforcement of Brazil’s newly operational Digital ECA, additional safety regulations and details regarding the under-16 social media ban in the UK, and continued U.S. state-level activity.
  • Regulatory overlaps, particularly as safety and privacy regulators pursue infringements arising from the same underlying facts under different legal frameworks.

***

The Covington team is closely monitoring these developments and is well placed to help clients assess their practical implications. Please reach out to a member of the team to discuss how they may affect your organization.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Dan Cooper Dan Cooper

Daniel Cooper is co-chair of Covington’s Data Privacy and Cyber Security Practice, and advises clients on information technology regulatory and policy issues, particularly data protection, consumer protection, AI, and data security matters. He has over 20 years of experience in the field, representing…

Daniel Cooper is co-chair of Covington’s Data Privacy and Cyber Security Practice, and advises clients on information technology regulatory and policy issues, particularly data protection, consumer protection, AI, and data security matters. He has over 20 years of experience in the field, representing clients in regulatory proceedings before privacy authorities in Europe and counseling them on their global compliance and government affairs strategies. Dan regularly lectures on the topic, and was instrumental in drafting the privacy standards applied in professional sport.

According to Chambers UK, his “level of expertise is second to none, but it’s also equally paired with a keen understanding of our business and direction.” It was noted that “he is very good at calibrating and helping to gauge risk.”

Dan is qualified to practice law in the United States, the United Kingdom, Ireland and Belgium. He has also been appointed to the advisory and expert boards of privacy NGOs and agencies, such as the IAPP’s European Advisory Board, Privacy International and the European security agency, ENISA.

Photo of Jadzia Pierce Jadzia Pierce

Jadzia Pierce advises clients developing and deploying technology on a range of regulatory matters, including the intersection of AI governance and data protection. Jadzia draws on her experience in senior in house leadership roles and extensive, hands on engagement with regulators worldwide. Prior…

Jadzia Pierce advises clients developing and deploying technology on a range of regulatory matters, including the intersection of AI governance and data protection. Jadzia draws on her experience in senior in house leadership roles and extensive, hands on engagement with regulators worldwide. Prior to rejoining Covington in 2026, Jadzia served as Global Data Protection Officer at Microsoft, where she oversaw and advised on the company’s GDPR/UK GDPR program and acted as a primary point of contact for supervisory authorities on matters including AI, children’s data, advertising, and data subject rights.

Jadzia previously was Director of Microsoft’s Global Privacy Policy function and served as Associate General Counsel for Cybersecurity at McKinsey & Company. She began her career at Covington, advising Fortune 100 companies on privacy, cybersecurity, incident preparedness and response, investigations, and data driven transactions.

At Covington, Jadzia helps clients operationalize defensible, scalable approaches to AI enabled products and services, aligning privacy and security obligations with rapidly evolving regulatory frameworks across jurisdictions—with a particular focus on anticipating enforcement trends and navigating inter regulator dynamics.

Photo of Kristof Van Quathem Kristof Van Quathem

Kristof Van Quathem advises clients on information technology matters and policy, with a focus on data protection, cybercrime and various EU data-related initiatives, such as the Data Act, the AI Act and EHDS.

Kristof has been specializing in this area for over twenty…

Kristof Van Quathem advises clients on information technology matters and policy, with a focus on data protection, cybercrime and various EU data-related initiatives, such as the Data Act, the AI Act and EHDS.

Kristof has been specializing in this area for over twenty years and developed particular experience in the life science and information technology sectors. He counsels clients on government affairs strategies concerning EU lawmaking and their compliance with applicable regulatory frameworks, and has represented clients in non-contentious and contentious matters before data protection authorities, national courts and the Court of the Justice of the EU.

Kristof is admitted to practice in Belgium.

Photo of Atli Stannard Atli Stannard

Atli Stannard advises clients on EU trade law and policy, technology regulation, and the governance of strategically significant industrial sectors, with a particular focus on the geoeconomic forces shaping European regulation, industrial policy, and the transatlantic relationship. Clients describe him as providing “exceptional…

Atli Stannard advises clients on EU trade law and policy, technology regulation, and the governance of strategically significant industrial sectors, with a particular focus on the geoeconomic forces shaping European regulation, industrial policy, and the transatlantic relationship. Clients describe him as providing “exceptional levels of insight.”

Atli guides clients in highly regulated industries through complex EU policymaking processes, protecting and advancing their core business and regulatory priorities. He is a member of the firm’s Public Policy, International Trade, Sustainability, and Business & Human Rights practices.

Atli’s trade practice covers the full suite of EU trade instruments, including the EU Anti‑Coercion Instrument, trade defence investigations, customs classification and market‑access issues, investment-related tools (FDI and the foreign subsidies regulation), and environmental-related trade tools such as CBAM. He frequently advises on regulatory issues at the intersection of trade and technology—covering platform, data, AI, and competition policy—where digital and geoeconomic considerations converge.

His work also encompasses the EU frameworks governing medical technologies and other strategically important industrial sectors—such as automotive, and food and beverage—and includes supporting clients on environmental and EU ESG policymaking. Across these domains, he helps clients identify regulatory risks early, anticipate institutional dynamics, and build clear, actionable strategies—working closely with them to engage effectively with the European Commission, European Parliament, Council of the EU, and Member State and UK governments.

Photo of Anna Sophia Oberschelp de Meneses Anna Sophia Oberschelp de Meneses

Anna Sophia Oberschelp de Meneses advises on EU data protection, cybersecurity, and consumer law. Her practice covers the full range of Europe’s digital regulatory framework, including GDPR, ePrivacy, NIS2, the Cyber Resilience Act, the AI Act, the Digital Services Act, the Data Act…

Anna Sophia Oberschelp de Meneses advises on EU data protection, cybersecurity, and consumer law. Her practice covers the full range of Europe’s digital regulatory framework, including GDPR, ePrivacy, NIS2, the Cyber Resilience Act, the AI Act, the Digital Services Act, the Data Act, the European Health Data Space, and EU consumer protection law, including product safety, product liability, and consumer rights legislation. She focuses on the operational side of compliance — helping clients design policies and processes, draft documentation, and build the internal frameworks needed to meet regulatory requirements in practice.

She also advises on contentious matters, drawing on experience managing investigations before national regulators and proceedings before national courts and the Court of Justice of the European Union. She works closely with Covington’s disputes teams on matters at the intersection of regulatory compliance and litigation.

Photo of Diego Bonomo Diego Bonomo

Diego Bonomo is a senior advisor in the firm’s London office. Diego, a non-lawyer, has more than 25 years of Brazil regulatory, trade, and foreign affairs experience at leading business associations, think tanks, companies, and academic institutions. Diego also served in the Brazilian…

Diego Bonomo is a senior advisor in the firm’s London office. Diego, a non-lawyer, has more than 25 years of Brazil regulatory, trade, and foreign affairs experience at leading business associations, think tanks, companies, and academic institutions. Diego also served in the Brazilian government.

Before joining the firm, Diego was Team Leader of the Brazil Trade Facilitation Program at Palladium and Executive Manager of International Affairs at Brazil’s National Confederation of Industry — CNI. At the U.S. Chamber of Commerce, he served as Senior Director of the International Division and Senior Director for Policy of the Brazil-U.S. Business Council. Diego also was Executive Director of the Brazil Industries Coalition — BIC, the leading Brazilian business coalition in the United States, and General Coordinator of Foreign and Trade Affairs at the Federation of Industries of the State of São Paulo — FIESP. He previously served in the Office of the President of Brazil as advisor to the Minister of Long-Term Planning.

Diego holds a bachelor’s and master’s degree in international relations from the Pontifical Catholic University of São Paulo.

Photo of John Bowers John Bowers

John Bowers is an associate in the firm’s Washington, DC office. He is a member of the Data Privacy and Cybersecurity Practice Group and the Technology and Communications Regulation Practice Group.

John advises clients on a wide range of privacy and communications issues…

John Bowers is an associate in the firm’s Washington, DC office. He is a member of the Data Privacy and Cybersecurity Practice Group and the Technology and Communications Regulation Practice Group.

John advises clients on a wide range of privacy and communications issues, including compliance with telecommunications regulations and U.S. state and federal privacy laws.

Photo of Sam Jungyun Choi Sam Jungyun Choi

Recognized by Law.com International as a Rising Star (2023), Sam Jungyun Choi is an associate in the technology regulatory group in Brussels. She advises leading multinationals on European and UK data protection law and new regulations and policy relating to innovative technologies, such…

Recognized by Law.com International as a Rising Star (2023), Sam Jungyun Choi is an associate in the technology regulatory group in Brussels. She advises leading multinationals on European and UK data protection law and new regulations and policy relating to innovative technologies, such as AI, digital health, and autonomous vehicles.

Sam is an expert on the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act, having advised on these laws since they started to apply. In recent years, her work has evolved to include advising companies on new data and digital laws in the EU, including the AI Act, Data Act and the Digital Services Act.

Sam’s practice includes advising on regulatory, compliance and policy issues that affect leading companies in the technology, life sciences and gaming companies on laws relating to privacy and data protection, digital services and AI. She advises clients on designing of new products and services, preparing privacy documentation, and developing data and AI governance programs. She also advises clients on matters relating to children’s privacy and policy initiatives relating to online safety.

Laura Schukraft

Laura Schukraft is a Legal Intern who attended the Faculty of Law of the University of Fribourg and the European Legal Studies Department of the College of Europe.